CSRF Vulnerability in Agentejo Cockpit - Agentejo
CVE-2018-15539

8.8HIGH

Key Information:

Vendor

Agentejo

Status
Vendor
CVE Published:
15 October 2018

What is CVE-2018-15539?

The Agentejo Cockpit CMS is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability due to the absence of an anti-CSRF protection mechanism. This flaw allows attackers to exploit the system by changing critical settings such as API tokens and passwords, potentially compromising user accounts and data integrity. Users of the Cockpit CMS should implement necessary security measures to safeguard against these types of attacks.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.